VYPR

CVEs

31,787 total · page 315 of 636

  • CVE-2022-37090CriAug 25, 2022
    risk 0.64cvss 9.8epss 0.01

    H3C H200 H200V100R004 was discovered to contain a stack overflow via the function Edit_BasicSSID.

  • CVE-2022-37089CriAug 25, 2022
    risk 0.64cvss 9.8epss 0.01

    H3C H200 H200V100R004 was discovered to contain a stack overflow via the function EditMacList.

  • CVE-2022-37088CriAug 25, 2022
    risk 0.64cvss 9.8epss 0.01

    H3C H200 H200V100R004 was discovered to contain a stack overflow via the function SetAP5GWifiById.

  • CVE-2022-37087CriAug 25, 2022
    risk 0.64cvss 9.8epss 0.01

    H3C H200 H200V100R004 was discovered to contain a stack overflow via the function SetMobileAPInfoById.

  • CVE-2022-37086CriAug 25, 2022
    risk 0.64cvss 9.8epss 0.01

    H3C H200 H200V100R004 was discovered to contain a stack overflow via the function Asp_SetTimingtimeWifiAndLed.

  • CVE-2022-37085CriAug 25, 2022
    risk 0.64cvss 9.8epss 0.01

    H3C H200 H200V100R004 was discovered to contain a stack overflow via the AddWlanMacList function.

  • CVE-2022-37073CriAug 25, 2022
    risk 0.64cvss 9.8epss 0.01

    H3C GR-1200W MiniGRW1A0V100R006 was discovered to contain a stack overflow via the function UpdateWanModeMulti.

  • CVE-2022-37072CriAug 25, 2022
    risk 0.64cvss 9.8epss 0.01

    H3C GR-1200W MiniGRW1A0V100R006 was discovered to contain a stack overflow via the function UpdateWanLinkspyMulti.

  • CVE-2022-37071CriAug 25, 2022
    risk 0.64cvss 9.8epss 0.01

    H3C GR-1200W MiniGRW1A0V100R006 was discovered to contain a stack overflow via the function UpdateOne2One.

  • CVE-2022-37070CriAug 25, 2022
    risk 0.65cvss 9.8epss 0.11

    H3C GR-1200W MiniGRW1A0V100R006 was discovered to contain a command injection vulnerability via the param parameter at DelL2tpLNSList.

  • CVE-2022-37069CriAug 25, 2022
    risk 0.64cvss 9.8epss 0.01

    H3C GR-1200W MiniGRW1A0V100R006 was discovered to contain a stack overflow via the function UpdateSnat.

  • CVE-2022-37068CriAug 25, 2022
    risk 0.64cvss 9.8epss 0.01

    H3C GR-1200W MiniGRW1A0V100R006 was discovered to contain a stack overflow via the function UpdateMacCloneFinal.

  • CVE-2022-37067CriAug 25, 2022
    risk 0.64cvss 9.8epss 0.01

    H3C GR-1200W MiniGRW1A0V100R006 was discovered to contain a stack overflow via the function UpdateWanParamsMulti.

  • CVE-2022-37066CriAug 25, 2022
    risk 0.64cvss 9.8epss 0.01

    H3C GR-1200W MiniGRW1A0V100R006 was discovered to contain a stack overflow via the function UpdateDDNS.

  • CVE-2022-36520CriAug 25, 2022
    risk 0.64cvss 9.8epss 0.01

    H3C GR-1200W MiniGRW1A0V100R006 was discovered to contain a stack overflow via the function DEleteusergroup.

  • CVE-2022-36519CriAug 25, 2022
    risk 0.64cvss 9.8epss 0.01

    H3C GR-1200W MiniGRW1A0V100R006 was discovered to contain a stack overflow via the function AddWlanMacList.

  • CVE-2022-36518CriAug 25, 2022
    risk 0.64cvss 9.8epss 0.01

    H3C GR-1200W MiniGRW1A0V100R006 was discovered to contain a stack overflow via the function EditWlanMacList.

  • CVE-2022-36517CriAug 25, 2022
    risk 0.64cvss 9.8epss 0.01

    H3C GR-1200W MiniGRW1A0V100R006 was discovered to contain a stack overflow via the function debug_wlan_advance.

  • CVE-2022-36516CriAug 25, 2022
    risk 0.64cvss 9.8epss 0.01

    H3C GR-1200W MiniGRW1A0V100R006 was discovered to contain a stack overflow via the function ap_version_check.

  • CVE-2022-36515CriAug 25, 2022
    risk 0.64cvss 9.8epss 0.01

    H3C GR-1200W MiniGRW1A0V100R006 was discovered to contain a stack overflow via the function addactionlist.

  • CVE-2022-36514CriAug 25, 2022
    risk 0.64cvss 9.8epss 0.01

    H3C GR-1200W MiniGRW1A0V100R006 was discovered to contain a stack overflow via the function WanModeSetMultiWan.

  • CVE-2022-36513CriAug 25, 2022
    risk 0.64cvss 9.8epss 0.01

    H3C GR-1200W MiniGRW1A0V100R006 was discovered to contain a stack overflow via the function edditactionlist.

  • CVE-2022-36511CriAug 25, 2022
    risk 0.64cvss 9.8epss 0.01

    H3C GR-1200W MiniGRW1A0V100R006 was discovered to contain a stack overflow via the function EditApAdvanceInfo.

  • CVE-2022-34960CriAug 25, 2022
    risk 0.64cvss 9.8epss 0.01

    The container package in MikroTik RouterOS 7.4beta4 allows an attacker to create mount points pointing to symbolic links, which resolve to locations on the host device. This allows the attacker to mount any arbitrary file to any location on the host.

  • CVE-2022-32839CriAug 24, 2022
    risk 0.64cvss 9.8epss 0.03

    The issue was addressed with improved bounds checks. This issue is fixed in macOS Monterey 12.5, macOS Big Sur 11.6.8, Security Update 2022-005 Catalina, iOS 15.6 and iPadOS 15.6, tvOS 15.6, watchOS 8.7. A remote user may cause an unexpected app termination or arbitrary code…

  • CVE-2022-37181CriAug 24, 2022
    risk 0.64cvss 9.8epss 0.01

    72crm 9.0 has an Arbitrary file upload vulnerability.

  • CVE-2022-2234CriAug 24, 2022
    risk 0.68cvss 9.9epss 0.41

    An authenticated mySCADA myPRO 8.26.0 user may be able to modify parameters to run commands directly in the operating system.

  • CVE-2022-20122CriAug 24, 2022
    risk 0.64cvss 9.8epss 0.00

    The PowerVR GPU driver allows unprivileged apps to allocated pinned memory, unpin it (which makes it available to be freed), and continue using the page in GPU calls. No privileges required and this results in kernel memory corruption.Product: AndroidVersions: Android SoCAndroid…

  • CVE-2021-39815CriAug 24, 2022
    risk 0.64cvss 9.8epss 0.00

    The PowerVR GPU driver allows unprivileged apps to allocated pinned memory, unpin it (which makes it available to be freed), and continue using the page in GPU calls. No privileges required and this results in kernel memory corruption.Product: AndroidVersions: Android SoCAndroid…

  • CVE-2022-38078CriAug 24, 2022
    risk 0.64cvss 9.8epss 0.02

    Movable Type XMLRPC API provided by Six Apart Ltd. contains a command injection vulnerability. Sending a specially crafted message by POST method to Movable Type XMLRPC API may allow arbitrary Perl script execution, and an arbitrary OS command may be executed through it.…

  • CVE-2022-35115CriAug 23, 2022
    risk 0.64cvss 9.8epss 0.01

    IceWarp WebClient DC2 - Update 2 Build 9 (13.0.2.9) was discovered to contain a SQL injection vulnerability via the search parameter at /webmail/server/webmail.php.

  • CVE-2022-37113CriAug 23, 2022
    risk 0.65cvss 9.8epss 0.14

    Bluecms 1.6 has SQL injection in line 132 of admin/area.php

  • CVE-2022-37112CriAug 23, 2022
    risk 0.64cvss 9.8epss 0.01

    BlueCMS 1.6 has SQL injection in line 55 of admin/model.php

  • CVE-2022-37111CriAug 23, 2022
    risk 0.64cvss 9.8epss 0.01

    BlueCMS 1.6 has SQL injection in line 132 of admin/article.php

  • CVE-2022-37223CriAug 23, 2022
    risk 0.64cvss 9.8epss 0.01

    JFinal CMS 5.1.0 is vulnerable to SQL Injection via /jfinal_cms/system/role/list.

  • CVE-2022-37199CriAug 23, 2022
    risk 0.64cvss 9.8epss 0.01

    JFinal CMS 5.1.0 is vulnerable to SQL Injection via /jfinal_cms/system/user/list.

  • CVE-2022-36261CriAug 23, 2022
    risk 0.59cvss 9.1epss 0.01

    An arbitrary file deletion vulnerability was discovered in taocms 3.0.2, that allows attacker to delete file in server when request url admin.php?action=file&ctrl=del&path=/../../../test.txt

  • CVE-2021-42627CriAug 23, 2022
    risk 0.69cvss 9.8epss 0.63

    The WAN configuration page "wan.htm" on D-Link DIR-615 devices with firmware 20.06 can be accessed directly without authentication which can lead to disclose the information about WAN settings and also leverage attacker to modify the data fields of page.

  • CVE-2022-35733CriAug 23, 2022
    risk 0.64cvss 9.8epss 0.01

    Missing authentication for critical function vulnerability in UNIMO Technology digital video recorders (UDR-JA1004/JA1008/JA1016 firmware versions v1.0.20.13 and earlier, and UDR-JA1016 firmware versions v2.0.20.13 and earlier) allows a remote unauthenticated attacker to execute…

  • CVE-2022-34919CriAug 23, 2022
    risk 0.64cvss 9.8epss 0.01

    The file upload wizard in Zengenti Contensis Classic before 15.2.1.79 does not correctly check that a user has authenticated. By uploading a crafted aspx file, it is possible to execute arbitrary commands.

  • CVE-2021-42232CriAug 23, 2022
    risk 0.64cvss 9.8epss 0.02

    TP-Link Archer A7 Archer A7(US)_V5_210519 is affected by a command injection vulnerability in /usr/bin/tddp. The vulnerability is caused by the program taking part of the received data packet as part of the command. This will cause an attacker to execute arbitrary commands on…

  • CVE-2022-38667CriAug 22, 2022
    risk 0.00cvss 9.8epss 0.02

    HTTP applications (servers) based on Crow through 1.0+4 may allow a Use-After-Free and code execution when HTTP pipelining is used. The HTTP parser supports HTTP pipelining, but the asynchronous Connection layer is unaware of HTTP pipelining. Specifically, the Connection layer…

  • CVE-2022-30547CriAug 22, 2022
    risk 0.69cvss 9.9epss 0.64

    A directory traversal vulnerability exists in the unzipDirectory functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can send an HTTP request to trigger this vulnerability.

  • CVE-2022-28712CriAug 22, 2022
    risk 0.59cvss 9.0epss 0.02

    A cross-site scripting (xss) vulnerability exists in the videoAddNew functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get an authenticated user to send a crafted HTTP…

  • CVE-2022-26842CriAug 22, 2022
    risk 0.63cvss 9.6epss 0.03

    A reflected cross-site scripting (xss) vulnerability exists in the charts tab selection functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get an authenticated user to…

  • CVE-2022-35583CriAug 22, 2022
    risk 0.68cvss 9.8epss 0.11

    wkhtmlTOpdf 0.12.6 is vulnerable to SSRF which allows an attacker to get initial access into the target's system by injecting iframe tag with initial asset IP address on it's source. This allows the attacker to takeover the whole infrastructure by accessing their internal assets.

  • CVE-2022-35150CriAug 22, 2022
    risk 0.64cvss 9.8epss 0.01

    Baijicms v4 was discovered to contain an arbitrary file upload vulnerability.

  • CVE-2022-37134CriAug 22, 2022
    risk 0.65cvss 9.8epss 0.21

    D-link DIR-816 A2_v1.10CNB04.img is vulnerable to Buffer Overflow via /goform/form2Wan.cgi. When wantype is 3, l2tp_usrname will be decrypted by base64, and the result will be stored in v94, which does not check the size of l2tp_usrname, resulting in stack overflow.

  • CVE-2022-34858CriAug 22, 2022
    risk 0.64cvss 9.8epss 0.01

    Authentication Bypass vulnerability in miniOrange OAuth 2.0 client for SSO plugin <= 1.11.3 at WordPress.

  • CVE-2022-34149CriAug 22, 2022
    risk 0.64cvss 9.8epss 0.01

    Authentication Bypass vulnerability in miniOrange WP OAuth Server plugin <= 3.0.4 at WordPress.